2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-37605HIGH7.5In version 6.5 Microchip MiWi software and all previous versions including legacy products, the stack is validating only...
CVE-2021-37604HIGH7.5In version 6.5 of Microchip MiWi software and all previous versions including legacy products, there is a possibility of...
CVE-2021-38095HIGH7.5The REST API in Planview Spigit 4.5.3 allows remote unauthenticated attackers to query sensitive user accounts data, as ...
CVE-2021-32603MEDIUM6.5A server-side request forgery (SSRF) (CWE-918) vulnerability in FortiManager and FortiAnalyser GUI 7.0.0, 6.4.5 and belo...
CVE-2021-32598MEDIUM4.3An improper neutralization of CRLF sequences in HTTP headers ('HTTP Response Splitting') vulnerability In FortiManager a...
CVE-2021-3539MEDIUM5.4EspoCRM 6.1.6 and prior suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in processing user-...
CVE-2021-36805MEDIUM4.8Akaunting version 2.1.12 and earlier suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in the...
CVE-2021-36804HIGH8.1Akaunting version 2.1.12 and earlier suffers from a password reset spoofing vulnerability, wherein an attacker can proxy...
CVE-2021-36803MEDIUM5.4Akaunting version 2.1.12 and earlier suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in pro...
CVE-2021-36802MEDIUM6.5Akaunting version 2.1.12 and earlier suffers from a denial-of-service issue that is triggered by setting a malformed 'lo...
CVE-2021-36801HIGH8.1Akaunting version 2.1.12 and earlier suffers from an authentication bypass issue in the user-controllable field, compani...
CVE-2021-36800CRITICAL9.1Akaunting version 2.1.12 and earlier suffers from a code injection issue in the Money.php component of the application. ...
CVE-2021-31869HIGH7.5Pimcore AdminBundle version 6.8.0 and earlier suffers from a SQL injection issue in the specificID variable used by the ...
CVE-2021-31867HIGH7.5Pimcore Customer Data Framework version 3.0.0 and earlier suffers from a Boolean-based blind SQL injection issue in the ...
CVE-2021-38115MEDIUM6.5read_header_tga in gd_tga.c in the GD Graphics Library (aka LibGD) through 2.3.2 allows remote attackers to cause a deni...
CVE-2021-38114MEDIUM5.5libavcodec/dnxhddec.c in FFmpeg 4.4 does not check the return value of the init_vlc function, a similar issue to CVE-201...
CVE-2021-38113MEDIUM5.4In addBouquet in js/bqe.js in OpenWebif (aka e2openplugin-OpenWebif) through 1.4.7, inserting JavaScript into the Add Bo...
CVE-2021-32465HIGH8.8An incorrect permission preservation vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 ...
CVE-2021-32464HIGH7.8An incorrect permission assignment privilege escalation vulnerability in Trend Micro Apex One, Apex One as a Service and...
CVE-2021-24014MEDIUM6.1Multiple instances of improper neutralization of input during web page generation vulnerabilities in FortiSandbox before...
CVE-2021-22124HIGH7.5An uncontrolled resource consumption (denial of service) vulnerability in the login modules of FortiSandbox 3.2.0 throug...
CVE-2021-20028CRITICAL9.8Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Acce...
CVE-2021-38111HIGH8.8The DEF CON 27 badge allows remote attackers to exploit a buffer overflow by sending an oversized packet via the NFMI (N...
CVE-2021-34707MEDIUM6.5A vulnerability in the REST API of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remot...
CVE-2021-32793MEDIUM4.8Pi-hole's Web interface provides a central location to manage a Pi-hole instance and review performance statistics. Prio...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now